SAP's Matthew Valites on Why He Is a Proponent of Detection as Code
Apr 9, 2024
auto_awesome
Matthew Valites, Director of Threat Detection & Operational Strategy at SAP, discusses the best threat detection approaches, using detection as code, and the role of GenAI in the future security landscape. He also shares actionable lessons from his book, 'Crafting the Infosec Playbook'.
Implementing operational detections like user logins uncovers anomalies for wins in threat detection.
Adapting detection strategies to diverse environments and using tailored macros enhances accuracy and efficiency at scale.
Deep dives
Approaching Threat Detection at Scale
Ensuring accurate baseline tuning is crucial for effective threat detection. Implementing operational detections, like user logins, uncovers anomalies, providing wins in detection. The podcast highlights the importance of Detection at Scale for modern security practices. With data volume growing and attack surfaces expanding, staying ahead of threats becomes paramount.
Matt Velitis on Professional Journey & Threat Detection
Matt Velitis, from SAP, discusses his career evolution from Linux/Unix to threat detection at SAP. Understanding the intricate balance between investigation and response within the SOC is critical. Matt emphasizes the importance of building threat detection capabilities in alignment with the organization's environment. He talks about the significance of adapting detection strategies to diverse and large-scale environments.
Prioritizing Detection Techniques for Threat Identification
Implementing a threat-informed approach helps prioritize detection techniques effectively. Focusing on applicable tactics and technologies enables better visibility and operational response. Building a catalog of static detection rules forms the foundation for comprehensive threat identification. Streamlining alerting processes and correlation enhances detection accuracy and efficiency at scale.
Enhancing Detection Flexibility with Environment-Specific Tuning
Centralizing detections and utilizing environment-specific tuning macros allow for versatile threat identification. Matching detection logic to the unique attributes of each environment enhances accuracy. Automation aids in managing exclusions and fine-tuning detection rules, improving operational efficiency. By customizing detections at the macro level, organizations can maintain a singular catalog adaptable to diverse environments.
On this week's episode of the Detection at Scale podcast, Jack talks with Matthew Valites, Director of Threat Detection & Operational Strategy at SAP. They discuss which threat detection approach works the best, what metrics Matthew uses to gauge his programs, and why Matthew is a proponent of using detection as code.
Matthew also looks to the future and gives his prediction on what role technology such as GenAI will play in the security landscape. They close out their conversation with some actionable lessons from Matthew's book, Crafting the Infosec Playbook.
Topics discussed:
Which threat-detection approach works the best (hint: it's usually the one that provides the most visibility).
How Matthew manages the different logic in different environment using tailored macros.
What metrics Matthew uses to gauge his programs and how he keeps track of those metrics.
Why Matthew is a huge proponent of using detection as code, including the CIDC element it brings.
What makes GenAI so exciting, and what its role might be in the future.
How Matthew tries to take care of his team's mental and physical health.
Actionable lessons from the book Matthew co-authored, “Crafting the Infosec Playbook”, such as espousing the values of a service-based approach.
Get the Snipd podcast app
Unlock the knowledge in podcasts with the podcast player of the future.
AI-powered podcast player
Listen to all your favourite podcasts with AI-powered features
Discover highlights
Listen to the best highlights from the podcasts you love and dive into the full episode
Save any moment
Hear something you like? Tap your headphones to save it with AI-generated key takeaways
Share & Export
Send highlights to Twitter, WhatsApp or export them to Notion, Readwise & more
AI-powered podcast player
Listen to all your favourite podcasts with AI-powered features
Discover highlights
Listen to the best highlights from the podcasts you love and dive into the full episode